SHINDO5

CAMPFIRE, Inc.

Financial & payment82,465recordsup to 225,846 people affected

POSSIBLE LEAKBank account / Postal addressUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Apr 3, 2026
Detected
Apr 2, 2026 22:00 JST
Detection to disclosure
1 day
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName
ContactAddress, Phone number, Email address
Financial & paymentBank account details
Account dataUser name
System & internalSome source code (may have been viewed)

Not leaked

  • Credit card information not included

How many

  • People up to 225,846 people
  • Project owners (since February 2021) 120,929 records
  • Backers 130,155 records
  • User names only (to 5 March 2025) 1,282 records
  • Records with bank account details 82,465 records

Who is affected

  • Project owners
  • Backers

Cause

Unauthorized access to a GitHub account used for system administration led to access to the database

Timeline

  1. Unauthorized access to the GitHub account detected and blocked
  2. Announced the GitHub access (no personal data leak confirmed at that time)
  3. Database access confirmed
  4. Announced possible exposure of up to 225,846 people and began notifying them
  5. Individuals notified
  6. Yokohama DeNA BayStars announced the impact on backers of its victory-parade crowdfunding

Response

  • Blocked the entry point
  • Forensic investigation
  • Notified individuals
  • Hotline
  • Phishing warning
  • Password reset

Blocked the account and investigated with outside experts; reported to the PPC and consulted police; notified affected people from 24 April and opened a hotline (0120-188-070) on 28 April; warned about phishing and password reuse

What you should do

  1. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources